Denial of Service Vulnerability in pypdf by PyPDF
CVE-2026-57204

6.9MEDIUM

Key Information:

Vendor

Py-PDF

Status
Vendor
CVE Published:
30 June 2026

What is CVE-2026-57204?

The pypdf library is susceptible to Denial of Service (DoS) attacks due to the improper handling of maliciously crafted PDF files. Specifically, prior to version 6.13.3, an attacker could exploit this vulnerability by creating a PDF that leads to excessive memory consumption. This occurs because the library occasionally ignores the defined MAX_DECLARED_STREAM_LENGTH when parsing content streams that lack a /Length value. Users are strongly recommended to update to version 6.13.3 or later to mitigate this issue.

Affected Version(s)

pypdf < 6.13.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.